vendor:
HomePagePrint
by:
UNYUN
7.5
CVSS
HIGH
Buffer Overflow
120 (Buffer Copy without Checking Size of Input)
CWE
Product Name: HomePagePrint
Affected Version From: 1.0.7
Affected Version To: 1.0.7
Patch Exists: YES
Related CWE: N/A
CPE: a:ibm:homepageprint:1.0.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows98
2000
IBM HomePagePrint Version 1.0.7 Exploit for Windows98
Certain versions of the IBM Web page printout software 'IBM HomePagePrint' can in some instances be remotely exploited by malicious webservers. The problem lies in a buffer overflow in the code which handles IMG_SRC tags. If a page containing a specially constructed IMG SRC tag is previewed or printed using the IBM HomePagePrint software, arbitrary code can be run on the client.
Mitigation:
Upgrade to the latest version of IBM HomePagePrint software.